Privacy Policy
iban.link is designed with privacy at its core. This policy explains what data is processed and how.
Data we process
- Recipient name and IBAN – encrypted in your browser before being sent to the server. We cannot read this data.
- Your chosen alias – stored in plain text to enable your link.
- No IP addresses, no user agents, and no personal identifiers are logged or stored.
Encryption
All sensitive data (name and IBAN) is encrypted client-side using AES-GCM before it ever reaches our server. The encryption key is part of your edit link and never stored on the server. We have no way to decrypt your data.
Cookies
iban.link uses two cookies: one for your language preference (de/en/es) and one for your theme preference (light/dark). No tracking cookies, no third-party cookies are set. Our analytics tool (Umami) does not use cookies.
Analytics
iban.link uses Umami, a privacy-focused, open-source analytics tool. Umami does not use cookies, does not track personal data, and does not collect IP addresses. It is fully GDPR compliant. We use it solely to see anonymous page view counts.
Third parties
iban.link does not share any data with third parties. No advertising networks and no external tracking scripts are used. Our analytics tool (Umami) is self-hosted and does not transmit data to any third party.
Your rights
- You can delete your page at any time via your edit link.
- You can request information about stored data by contacting us.
- Under GDPR, you have the right to access, rectification, erasure, and data portability.
Contact
For privacy-related questions, contact us at hi@ahef.xyz.